read.internal.api_keys
The store’s API keys and every token generation each one has minted (id, name, scopes, status, expiry, last use) — NEVER the token itself, which is returned exactly once at creation and is unrecoverable afterwards. A key mid-rotation shows two live generations. Internal face only.
- Surface:
GET /v1/read/internal/api_keys· MCP toolread.internal.api_keys - Auth: ★ Internal read (operator) — a tenant credential is REQUIRED; requires the
admin.users.writescope. The tenant is resolved from the CALLER’s identity, never fromstore. Personal fields come back MASKED for an actor withoutpii.read(the shape is unchanged).
Params (JSON Schema)
Section titled “Params (JSON Schema)”{ "properties": {}, "type": "object"}Result (200)
Section titled “Result (200)”Open (unknown) — this capability does not declare an output schema.
Errors
Section titled “Errors”validation_failed (400) · not_found (404) · unauthorized (401) · forbidden (403)